U-Boot — Out-of-Bounds Write in IP Fragment Reassembly
U-Boot's IP fragment reassembly writes into the reassembly buffer using attacker-controlled fragment offset and length without adequate bounds checking, so a crafted fragmented packet sent during netboot writes out of bounds and corrupts adjacent memory.
- Advisory
- BYTERAY-2026-0212
- CVE
- CVE-2026-71971
- CWE
- CWE-787
- CVSS
- 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-07-28
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc3, builds with CONFIG_IP_DEFRAG enabled
- Fixed in
- 2026.10-rc3 (commit 04ca915d5bf39dda5d1bce62d04d2b59d293c5b9)
Executive Summary
When U-Boot is built with CONFIG_IP_DEFRAG and its network stack is active
(for example during a netboot), it reassembles fragmented IP packets into a
fixed buffer. The reassembly code trusts the fragment offset and length taken
from the packet, so an attacker who can send IP packets to the device can drive
a write past the end of that buffer. The result is attacker-influenced memory
corruption inside the bootloader, reachable over the network with no
authentication.
Affected Products and Versions
- Product: U-Boot, IP fragment reassembly in
net/net.c(__net_defragment()). - Affected: U-Boot before 2026.10-rc3, in builds with
CONFIG_IP_DEFRAGenabled. - Fixed: 2026.10-rc3 and later.
Technical Details
__net_defragment() reassembles fragmented IP datagrams into a reassembly
buffer. The fragment offset and length are taken from the received packet and
used to place fragment data into the buffer without an adequate bounds check. A
crafted fragment with a non-zero offset and the More-Fragments flag set places
data past the end of the reassembly buffer, an out-of-bounds write of
attacker-controlled bytes at an attacker-influenced offset. The path is only
present when CONFIG_IP_DEFRAG is enabled.
Reachability and Preconditions
- The device is running U-Boot networking (for example during a netboot) and is
built with
CONFIG_IP_DEFRAG. - Any host that can send IP packets to the device can reach the parser. No authentication and no user interaction are required.
Impact
An out-of-bounds write that corrupts memory adjacent to the reassembly buffer and crashes the bootloader (denial of service). Because the overflow is an attacker-influenced memory-corruption primitive running inside U-Boot, before the operating system and any verified-boot handoff, it is a plausible path to code execution in the bootloader.
Remediation and Mitigation
Update U-Boot to 2026.10-rc3 or later, which contains commit
04ca915d5bf39dda5d1bce62d04d2b59d293c5b9. Where updating is not immediately
possible and IP defragmentation is not required, building without
CONFIG_IP_DEFRAG removes the vulnerable path; this disables reassembly of
fragmented IP packets.
Timeline
- 2026-07-28 — Vulnerability public and fix available upstream.
- 2026.10-rc3 — Fix released (commit
04ca915d5bf39dda5d1bce62d04d2b59d293c5b9). - 2026-09-29 — CVE-2026-71971 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.